Google has released the Chrome 149 update to address 18 vulnerabilities, with more than half attributed to use-after-free defects. Security impact is notable because these memory-safety issues can sometimes be leveraged for remote code execution. The practical takeaway for defenders: prioritize Chrome fleet updates and tighten browser sandbox hardening and exploit mitigation settings while patching rolls out.
Source: SecurityWeek
APT Turla’s STOCKSTAY backdoor: .NET implant engineered for stealthy, long-term espionage
Google Threat Intelligence Group describes the STOCKSTAY backdoor used by Turla against government and military targets in Ukraine, with broader suspected interest in European entities. The malware’s architecture relies on multi-component design, encrypted WebSocket C2 traffic, and IPC-based tasking, plus environment-based keying to limit analysis exposure. For security teams, this is a reminder that detection must account for toolchains (phishing+lures+RDP staging) and not just single binaries—especially where C2 is blended with legitimate service patterns.
Source: Google Cloud Threat Intelligence
Microsoft extends Windows 10 consumer ESU coverage by another year—through October 12, 2027
Microsoft has updated its Extended Security Updates (ESU) program documentation, extending free consumer coverage for Windows 10 by an additional year. While this reduces immediate risk for some unpatched Windows 10 systems, attackers will still target exposed configurations and legacy environments between now and the extended end date. Organizations should use the extra time to plan fleet transitions and ensure ESU-enabled devices still meet baseline patching, hardening, and monitoring requirements.
Source: Help Net Security
CISA warns of first-in-the-wild exploitation: PTC Windchill RCE added to KEV
CISA has added a remote code execution flaw in PTC Windchill (CVE-2026-12569) to its Known Exploited Vulnerabilities (KEV) catalog. “Known exploited” status is a signal to treat patching as urgent, validate exposure across Windchill deployments, and review logs for signs of attempted exploitation. If you manage industrial/product lifecycle systems, this is a direct call to bridge vulnerability management with real-world KEV prioritization.
Source: SecurityWeek
New backdoor “Mistic” surfaces in ransomware intrusions tied to the KongTuke (Woodgnat) access broker
Symantec reports that the Mistic backdoor has been observed across multiple sector-targeted intrusions since at least April 2026, including insurance, education, IT, and professional services. Researchers link the activity to Woodgnat (KongTuke), an initial access broker associated with ransomware operations, indicating a continuing pipeline from foothold to long-term persistence. Defenders should focus on hunting for stealthy persistence and long-lived access artifacts—not only the initial intrusion vector—because the operational goal appears to be staying quiet and resilient.
Source: Help Net Security
Fake domain renewal scams: attackers pressure website owners into paying fraudsters
Malwarebytes reports discovery of fake domain renewal notices and “convincing” scam sites designed to trick website owners into paying criminals. This social-engineering pattern targets a highly operational moment—domain registration renewal—where mistakes can quickly lead to loss of control of sites or services. Security teams should reinforce renewal verification processes (e.g., out-of-band checks, domain registrar security controls) and train staff not to act on urgent payment prompts delivered via unsolicited emails.
Source: Malwarebytes
You May Also Be Interested In...
Russia allegedly used Cellebrite tech after Cellebrite cut ties
NIST opens updated IoT security guidance to public review
What the Windows 10 ESU extension means for risk management